The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Scammers Up The ‘Rogueware’ War


Posted by George Hulme, Oct 17, 2009 04:44 PM

Attackers have been known to encrypt user files (such as happened with Gpcode), and then demand payment for the decryption key, for some time. These so-called rogueware, including scareware, attacks have been underway for some time. Now scammers have upped their attack tactics.


Attackers have now combined and escalated these two techniques. Instead of encrypting only a few files, they're are now throwing the victim’s system into a deep freeze until they purchase the rogueware that purports to unlock it.

From Kelly Jackson Higgins at DarkReading:


Researchers discovered a Trojan attack that basically freezes a user's system unless he purchases the rogueware, which goes for about $79.99. The Adware/TotalSecurity2009 rogueware attack doesn't just send fake popup security warnings -- it takes over the machine and renders all of its applications useless, except for Internet Explorer, which it uses to receive payment from the victim for the fake antivirus. "The system is completely crippled," says Sean-Paul Correll, threat researcher and security evangelist for PandaLabs, which found the new attack.

These attacks are big business, from a recent post XP Security 'Scareware' Scams Skyrocketing, and based on a research note from security appliance maker Fortinet found that there were 239,775 unique visitors to just one of the ten registered domains in use by scamsters at the time. If only a fraction of those visitors fell for the scareware scam, it could net hundreds of thousands a month.

Those types of attacks had been so successful that, as we covered about a month ago, Microsoft filed a series of five lawsuits that target malicious advertisements, which largely sell scareware:

The lawsuits allege that an unknown number of individuals using various business names distributed malicious software through Microsoft AdManager, the company's online advertising platform.

"These ads then lead to harmful or deceptive content," said Microsoft associate general counsel Tim Cranton, in a blog post. "For example, ads may redirect users to a Web site that advertises rogue security software, also known as scareware, that falsely claims to detect or prevent threats on the computer."

Now, not content with the profits of convincing users to download bogus anti-virus software (scareware) – that also often seconds as malicious keystroke sniffing malware – they’ve turned to virtually shutting the user out of their system until they pay-up.

Considering much profit can be made, and how easy it is to hijack legitimate Web sites to advertise scareware or even just simply trick users to download and install rogue applications, I'm afraid Correll is spot on with his analysis quoted in the DarkReading story referenced above:

Correll says it's only a matter of time before other rogueware developers emulate the ransom attack. "By forcing the user to pay so quickly, they are able to maximize their profitability before getting caught and removed," he says.


For my mobile security and technology observations, consider following me on Twitter.

« HCL Ties Its Pay To Boeing 787 Sales | Main | Friendfeed Traffic Drops Post-Acquisition And The First Employee Departs »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Here's to the First Responders!
  2. HPC Joins the Dummy Revolution?
  3. Detecting Scalability Problems With Intel Parallel Universe Portal


Join The InformationWeek Group On LinkedIn


                           


  1. 'Nexus One' Is Google's Android Phone For Consumers
  2. Motorola Droid Is Gadget Of The Year
  3. Microsoft's Non-Family Values
  4. HTC Droid Eris Receiving OTA Update From Verizon
  5. Windows Mobile 7 Now A Q4 Release


  1. Amazon Auctions Cloud Computation
  2. First Commercial LTE Network Goes Live
  3. Strong Authentication Not Strong Enough
  4. Apple Customers Report Flawed iMacs
  5. NASA Launches Comet-Hunting Space Camera
  6. Oracle Mobilizing MySQL Users

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007